Wired Intelligent Edge

 View Only
  • 1.  HP 2824 - PCM Critical Event

    Posted Nov 09, 2010 06:50 AM

    Hello,

     

    i have installed a Test-Version of the PCM 3.1. In the Event-Log of one Switch, i have many minor, major an critical events like this. IP 210 + 211 ar the HP2824.

    Can somebody help me what could be the problem?
    Thanks

    Event Details


    Event type:

    NIM Event

    Received from:

    192.168.202.211

    Date received:

    Tue Nov 09 12:20:00 CET 2010

    Date acknowledged:

    Event has not been acknowledged.

    Severity:

    Major

    Event Description

        ProCurve NBAD Small Frame IP Address Sweep Event
        
        Offender IP(s)
            192.168.202.8 - srv-ts1
        Offender MAC(s)
            00:04:23:dc:f9:b1 - Intel Corporation
        
        Victim IP(s)
            192.168.202.121 - verkauf_6
            192.168.202.159 - buchhaltung_3
            192.168.202.193 - besprechung_2
            192.168.202.206 - edv_adm
            192.168.202.2 - srv-file
            3 more...
        Victim MAC(s)
            00:19:99:0d:14:bb - Fujitsu Siemens Computers
            00:04:23:d9:96:f8 - Intel Corporation
            00:24:1d:74:5c:98 - Unknown Company
            00:0e:0c:c1:76:6c - Intel Corporation
            00:04:23:d5:b2:ba - Intel Corporation
            3 more...
        
        IP Protocol Number(s)
            IP Protocol 6 - TCP : Transmission Control Protocol
        
        Sampling Device(s)
            192.168.202.211 - Unresolvable DNS Name
        
        Vendor-Specific Data
            Magnitude - 8 victim address(es)
            Event ID Number - 9555

     

     

    Event Details


    Event type:

    NIM Event

    Received from:

    192.168.202.211

    Date received:

    Tue Nov 09 12:19:00 CET 2010

    Date acknowledged:

    Event has not been acknowledged.

    Severity:

    Critical

    Event Description

        ProCurve NBAD TCP Port Sweep Event
        
        Offender IP(s)
            192.168.202.254 - firewall.

        Offender MAC(s)
            00:01:69:00:b4:ac - Celestix Networks Pte Ltd.
        
        Victim IP(s)
            192.168.202.183 - technik_7

        Victim MAC(s)
            00:1f:d0:90:8e:77 - GIGA-BYTE TECHNOLOGY CO.,LTD.
        
        Offender and Victim TCP Port(s)
            192.168.202.254:8080/TCP (http-alt : HTTP Alternate (see port 80)) --> 192.168.202.183:2989/TCP (zarkov : ZARKOV Intelligent Agent Communication)
            192.168.202.254:8080/TCP (http-alt : HTTP Alternate (see port 80)) --> 192.168.202.183:3016/TCP (notify_srvr : Notify Server)
            192.168.202.254:8080/TCP (http-alt : HTTP Alternate (see port 80)) --> 192.168.202.183:3020/TCP (cifs : CIFS)
            192.168.202.254:8080/TCP (http-alt : HTTP Alternate (see port 80)) --> 192.168.202.183:2986/TCP (stonefalls : STONEFALLS)
            192.168.202.254:8080/TCP (http-alt : HTTP Alternate (see port 80)) --> 192.168.202.183:3010/TCP (gw : Telerate Workstation)
            17 more...
        Possible TCP Scan Type(s)
            TCP ACK Port Sweep
        
        Sampling Device(s)
            192.168.202.210 - Unresolvable DNS Name
            192.168.202.211 - Unresolvable DNS Name
        
        Vendor-Specific Data
            Magnitude - 22 scanned port(s)
            Event ID Number - 9378



  • 2.  RE: HP 2824 - PCM Critical Event

    Posted Nov 11, 2010 02:09 PM

    Hi,

     

    This is not a switch-specific problem.  Instead, these are events generated by a PCM security plugin called NIM (Network Immunity Manager) that you apparently are trying out along with your trial version of PCM.  Among other things, NIM analyzes sFlow data collected from devices throughout your network to look for traffic patterns that could indicate malicious behavior on the network; if it finds something that looks like a possibility it generates events of the sort you are asking about to tell you what behavior it found, who's doing it, and who they're doing it to.  The fact that the events are listed for your switch simply indicates that your switch provided the majority of sFlow data that was used to detect the reported behaviors.

     

    The first event you listed reports an IP sweep.  It means that the offender (192.168.202.8) has been contacting an unusually large number of IP addresses in a short period of time (using small IP frames in this case since it's a small frame IP sweep, which is often more indicative of an attack than sweeps using larger frames).  An IP sweep could indicate that software on the offender system is probing the network to see if there are unused IP addresses or to see if it can find a system that is vulnerable.  This behavior could also occur for many non-malicious reasons, for example if the reported offender node hosts some sort of network or host management application that is expected to be polling a large number of IP addresses periodically.  If this turns out to be expected behavior you can configure NIM to tell it not to report this kind of behavior from the offender anymore so that you don't have to see the same events continue since you're already concluded that they're not malicious.

     

    The second event you listed is a TCP ACK port sweep, which means that the offender (192.168.202.254) contacted an unusually large number of TCP ports on the victim (192.168.202.183) in a short period of time using TCP ACKs.  Given the offender node name (firewall) and the fact that the ports ACKed to are all HTTP alternates I'm guessing that there is nothing malicious here, though it's pretty interesting behavior to note.  This traffic pattern can indicate an offender searching for a vulnerable port on the victim node.  As with the IP sweep, if you determine that this traffic is innocuous and don't wish for further events of this type from this offender to be reported, just configure NIM so that it ignores this behavior for the offender IP from now on.

     

    Hopefully you find this kind of information useful.  NIM has turned up malicious attacks for many customers, but almost all of its users find that it's very good at educating them as to the traffic patterns that exist on their network even when it doesn't turn up anything malicious.  After you've "tuned" NIM so that you feel it's only reporting behaviors that may indeed indicate malware or a worm on the network you can even configure it to mitigate the spread of the potential issue by applying switch-based rate limiting to the port where the offender is connected to the network, putting the offender's port on a quarantine VLAN, or even enacting a MAC lockout against the offender or shutting their port off altogether so that they can't do anything more until you've looked at their system to investigate.

     

    Regards,

     

    SVB



  • 3.  RE: HP 2824 - PCM Critical Event

    Posted Nov 28, 2013 03:09 AM
    is this a problem or we can ignore such events like duplicate ip tcp port sweep n such